CVE-2017-12855
Summary
| CVE | CVE-2017-12855 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-15 16:29:00 UTC |
| Updated | 2017-11-15 02:29:00 UTC |
| Description | Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Xen |
Xen |
4.5.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.2 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.5 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.4 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.5 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.6 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.2 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.8.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.8.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.9.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.2 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.5.5 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.4 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.5 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.6.6 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.2 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.7.3 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.8.0 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.8.1 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.9.0 |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Xen CVE-2017-12855 Local Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Citrix XenServer Multiple Security Updates |
CONFIRM |
support.citrix.com |
|
| Xen Premature GTF Bit Clearing Lets Local Users on a Guet System Obtain Potentially Sensitive Information From Other Guest Systems - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-3969-1 xen |
DEBIAN |
www.debian.org |
|
| XSA-230 - Xen Security Advisories |
CONFIRM |
xenbits.xen.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500817 Alpine Linux Security Update for xen
- 504560 Alpine Linux Security Update for xen